<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower Access Controll Policy logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-access-controll-policy-logging/m-p/3350996#M924271</link>
    <description>&lt;P&gt;Thanks for reply!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think i'm hitting some bug. I noticed that in Policies&amp;gt;Actions&amp;gt;Alerts the syslog action was "not in use" even it was selected in few Rules. So I tried to deselect the syslog config from all my Access Control Rules than to deploy that configuration and after selecting the same syslog config on my rules and after deploying the syslog server&amp;nbsp;suddenly it worked!&lt;/P&gt;</description>
    <pubDate>Mon, 19 Mar 2018 16:29:26 GMT</pubDate>
    <dc:creator>dejan_jov1</dc:creator>
    <dc:date>2018-03-19T16:29:26Z</dc:date>
    <item>
      <title>Firepower Access Controll Policy logging</title>
      <link>https://community.cisco.com/t5/network-security/firepower-access-controll-policy-logging/m-p/3350830#M924269</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how can I send Syslog messeages&amp;nbsp; of Access Control Rule to an external Syslog&amp;nbsp;Server? I need to see which connections are Blocked or Allowed for specific Rules. In logging settings for Access Controll Rule I can configure Syslog Alert but I don't see any messages on Syslog server. I think that I have problem with selecting the right Facility but can't choose the right one. Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:31:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-access-controll-policy-logging/m-p/3350830#M924269</guid>
      <dc:creator>dejan_jov1</dc:creator>
      <dc:date>2020-02-21T15:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Access Controll Policy logging</title>
      <link>https://community.cisco.com/t5/network-security/firepower-access-controll-policy-logging/m-p/3350952#M924270</link>
      <description>&lt;P&gt;The default facility is normally OK unless your target syslog server has some specific setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you checked the syslog server to see if it is receiving packets on udp/514 from your FMC?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-access-controll-policy-logging/m-p/3350952#M924270</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-19T15:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Access Controll Policy logging</title>
      <link>https://community.cisco.com/t5/network-security/firepower-access-controll-policy-logging/m-p/3350996#M924271</link>
      <description>&lt;P&gt;Thanks for reply!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think i'm hitting some bug. I noticed that in Policies&amp;gt;Actions&amp;gt;Alerts the syslog action was "not in use" even it was selected in few Rules. So I tried to deselect the syslog config from all my Access Control Rules than to deploy that configuration and after selecting the same syslog config on my rules and after deploying the syslog server&amp;nbsp;suddenly it worked!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:29:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-access-controll-policy-logging/m-p/3350996#M924271</guid>
      <dc:creator>dejan_jov1</dc:creator>
      <dc:date>2018-03-19T16:29:26Z</dc:date>
    </item>
  </channel>
</rss>

